This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TROJAN virus TQR and TNH

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You have Java, it's just an older version that should be updated anyway. Let's do that, then try again.

Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 10.
  • Go to the Sun Java Website
  • Click on the download button next to Java Runtime Environment (JRE) 6 Update 10
  • Check the box next to I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement.
  • Click on the link Windows Offline Installation, jre-6u10-windows-i586-p.exe and save the downloaded file to your hard disk.
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 2 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file, and follow the on-screen instructions.
  • Reboot your computer
I don't know what the deal is, but it won't allow me to run kaspersky on either mozilla or on I.E. It says that java and javascript are enabled on both computers, and for some reason it won't even let me start it on mozilla. On I.E. it will go up to 20 percent, and then just stop. Let me know what you want me to do. Also, the computer is running smoothly and I havent had a pop-up or a sound ad in 2 days. Thanks for all the help.
Some PC's have issues with Kaspersky, not really sure why. We have other scanners we can try. Let's try Panda.

Run Panda's ActiveScan 2.0 from here and perform a full system scan.
  • Once you are on the Panda site click the "Scan your PC now" button
  • A new window will open…
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
  • If you are on a slow connection it will take about 15 minuites for the scanner to load.
  • Once scan is done, click "Export to:" and a save dialogue box will open
  • Save the log someplace you can find
  • Post the Panda scan results in your next reply
;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2008-11-12 07:25:23 PROTECTIONS: 2 MALWARE: 19 SUSPECTS: 11 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== Symantec Antivirus Corporate Edition 10.1 No Yes Windows Defender 1.1.4104.0 No No ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@trafficmp[1].txt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@doubleclick[2].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@atdmt[2].txt 00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@247realmedia[1].txt 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@tribalfusion[2].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\[removed][2].txt 00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@burstnet[2].txt 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@serving-sys[1].txt 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\[removed]-sys[1].txt 00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\[removed][2].txt 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@realmedia[2].txt 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@questionmarket[2].txt 00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Zach Greene\Cookies\zach_greene@zedo[1].txt 02900692 Application/Playmp3z HackTools No 0 Yes No C:\Documents and Settings\Zach Greene\Shared\joe brooks my heart will wait.zip[Setup.exe] 02900692 Application/Playmp3z HackTools No 0 Yes No C:\Documents and Settings\Zach Greene\Shared\my heart will wait joe brooks.zip[Setup.exe] 03378066 Application/Playmp3z HackTools No 0 Yes No C:\Documents and Settings\Zach Greene\Shared\joe brooks i will find.zip[Setup.exe] 04028359 Adware/AccesMembre Adware No 0 Yes No C:\Qoobox\Quarantine\C\DOCUME~1\ZACHGR~1\LOCALS~1\Temp\snapsnet.exe.vir 04034604 Adware/AccesMembre Adware No 0 No No C:\Qoobox\Quarantine\C\DOCUME~1\ZACHGR~1\LOCALS~1\Temp\snapsnet.exe.vir[QI191065.exe] 04043358 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{FE9C230A-3F48-4707-BF56-5054388ADFA7}\RP632\A0916800.exe 04043358 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{FE9C230A-3F48-4707-BF56-5054388ADFA7}\RP632\A0916822.exe 04059809 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\kqIRXP1n.exe_.vir 04059809 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{FE9C230A-3F48-4707-BF56-5054388ADFA7}\RP638\A0917097.exe 04059809 Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\kqIRXP1n.exe.vir ;=============================================================================== ================================================================================= =================== SUSPECTS Sent Location U ;=============================================================================== ================================================================================= =================== No C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP3.t$m No C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP7.t$m No C:\Qoobox\Quarantine\C\WINDOWS\system32\304qbxA4.exe.vir U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc4.exe U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc4.exe[32788R22FWJFW\psexec.cfexe] U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc5.exe U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc5.exe[32788R22FWJFW\psexec.cfexe] U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc5.exe[32788R22FWJFW\psexec.cfexe] U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc5.exe[32788R22FWJFW\psexec.cfexe] U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc4.exe[32788R22FWJFW\psexec.cfexe] U No C:\RECYCLER\S-1-5-21-602162358-2052111302-839522115-1003\Dc4.exe[32788R22FWJFW\psexec.cfexe] U ;=============================================================================== ================================================================================= =================== VULNERABILITIES Id Severity Description U ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= ===================
Mainly cookies (which are harmless) and files in combofix quarantine, along with restore points. We'll clean those out in a minute. A couple of items I do have questions on….

C:\Documents and Settings\Zach Greene\Shared\joe brooks my heart will wait.zip[Setup.exe]
C:\Documents and Settings\Zach Greene\Shared\my heart will wait joe brooks.zip[Setup.exe]
C:\Documents and Settings\Zach Greene\Shared\joe brooks i will find.zip[Setup.exe]

They are identified as hacktools. Do you know what they are? If not then I would advise removing them.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.
What happens when you run the uninstall routine? The Panda scan showed infected files in the combofix quarantine folder…

Generic Malware Virus/Trojan No 0 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\kqIRXP1n.exe.vir

You should delete the Qoobox folder if combofix is already gone. We will have to reset restore points also.

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which may be infected anyway).

Click Start>Help and Support>Undo changes to your computer with System Restore
Select Create A Restore Point then click Next. Give it a name it and then click Create

Click Start>Run and type Cleanmgr
Click the More Options Tab.
Click Clean Up in the System Restore section.
ok i deleted qoobox, and i got up to the last step in the clean up, but do i go back to the disk cleanup tab and press ok, because when i press clean up it doesn't really do anything.
It deletes all restore points except for the fresh new one you just set. I don't believe there is any confirmation after pressing ok. Should be good.

alright so i don't need to do the entire disk cleanup on the first tab?

No, that is used to clean up temp files, cache, ect….

In addition to updating and using what you currently have you may want to consider the following:

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. Here are some free and evalutation versions that provide
better security than the Windows Firewall. Comodo
Outpost Firewall
For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Use IE-SPYAD with Zoned Out -
Zoned Out with IE-SPYAD will block access to malicious websites so you cannot be redirected to them from an infected site or email. Instructions for set up and use can be found at the websites.
NOTE: Works with IE only.

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

I'll leave the thread open a few days in case you have questions or issues.

Regards,
Dave
Alright, thanks a lot for all of the help….so should I leave all of the programs that I have installed on my PC, besides that I think I am set, and I can't even tell you how happy I am that you could do this for me. It saved me a trip to a store that would have overcharged, so I appreciate it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI